Research Hub > How To Find and Solve Hidden Cloud Security Challenges
Case Study
5 min

How To Find and Solve Hidden Cloud Security Challenges

This nonprofit gained full visibility into its public cloud security posture with expert help from CDW.

It all started with a simple request: A nonprofit organization asked CDW to help them enhance security around a web application they hosted for their clients.

The national nonprofit, located in the southeastern U.S., had a small IT department with a new interim security director. The app in question had been built with code stored in GitHub and was essential to the nonprofit’s daily operations, but it had serious concerns about possible risks to client data, as well as to its own internal systems.

“We held a discovery call to learn more,” remembers Michael Cappiello, a cloud security solution architect with CDW’s Security Practice. “And the more we dug into it, the more it became apparent that their problem with this app was the tip of the iceberg.”

It wasn’t that the customer was in imminent danger of a security breach that might affect its infrastructure or expose client information. Instead, the main issue was that it couldn’t tell where its security threats were.

“They had no visibility when it came to the assets they had in their public cloud environments,” Cappiello explains. “And it wasn’t just this app; it was everything they were running. Their IT team was basically in the dark.”

Flying Blind in the Cloud

For the organization’s security director, the situation was a worst-case scenario. Tasked with protecting everything from servers and databases to storage buckets containing client documents, he was essentially trying to do his job blindfolded. The nonprofit leveraged Microsoft Azure for public cloud, but he could only guess where its vulnerabilities lay.

In a follow-up meeting, Cappiello was joined by his CDW colleague Isaac Oben, a cloud and application security specialist. Together, they dug deeper into the nonprofit’s visibility problems, gaining insight from its DevOps manager, and they learned that the organization had made two common mistakes in its approach to adopting and utilizing cloud services.

First, it had no security integration with its DevOps continuous integration/continuous deployment (CI/CD) pipeline. And more important, its team had been working under the assumption that the public cloud environment was already secure.

“Too many businesses think that cloud security is something they don’t need to worry about,” Oben says. “In doing that here, they were really at risk because they kind of just let everything go.”

Cappiello and Oben talked with their customer about the shared-responsibility model that’s so critical to success when using Azure or any public cloud service. Under that model (the details of which can vary slightly by vendor), the customer is responsible for the security of its own data.

“Once they saw that, they realized they needed to be more aware of what they were running in this world,” Cappiello says. Azure would secure the servers and the data centers, and all of the infrastructure supporting the organization’s cloud, but what it put in that cloud — its data and applications, its virtual machines, its client accounts and identities — “protecting that,” Cappiello explains, “was up to them.”

“It wasn’t that the customer was in imminent danger of a security breach that might affect its infrastructure or expose client information. Instead, the main issue was that it couldn’t tell where its security threats were.”

One Platform To See It All

With the security director and his team on board, Cappiello and Oben met with them again to run through potential next steps. One option, they told them, would be to deploy point solutions that addressed specific vulnerabilities. A cloud security posture management tool, for example, could help them find cloud misconfigurations, while container scanning software could locate and prevent security vulnerabilities in container images.

A better choice, though, was to deploy an all-in-one cloud-native application protection platform (CNAPP). The customer agreed.

“You may find point solutions that are best-of-breed in their particular areas, but the problem is, they’re working independently, and they’re usually not talking to each other,” Cappiello explains. The power of a CNAPP lies in its ability to correlate security alerts with contextual data across the entire software development life cycle. “It makes cloud security much easier by putting everything under a single pane of glass.”

Several vendors offer proven CNAPP products, but in this case, Cappiello and Oben decided the platform from Wiz best matched the organization’s needs. The solution connects directly to Azure and other public cloud providers via application programming interfaces (APIs), they explain, making it easy to deploy. Like other CNAPP platforms, it brings together everything from cloud workload protection to vulnerability management and Infrastructure as Code scanning. But where it really stands out is with its Wiz Security Graph, a tool that maps, analyzes and reveals potential risks across the user’s cloud technologies.

“We talked with the customer about their pain points, and a big one was their lack of staff or anything close to a dedicated security operations center team,” Cappiello says. “We recommended Wiz, as opposed to the competition, in part because it’s intuitive to use. You don’t necessarily have to be trained in cloud security to really put it to work.”

Another plus, Cappiello says, is the platform’s focus on cloud security posture management. Unlike other CNAPPs that use CSPM merely to detect misconfigurations, Wiz shows how an attacker might take advantage of vulnerabilities to break into systems and gain access to valuable data. “In terms of providing comprehensive visibility,” he explains, “that’s what Wiz really does best.”

Why Cloud Monitoring Matters

The process of monitoring cloud-based systems for risks and misconfigurations is known as cloud security posture management. Here’s why CSPM is an essential component of any cloud-native application protection platform.

80%

of cloud security breaches are a result of misconfigurations1

70%

of organizations say tool sprawl and visibility gaps are top barriers to cloud security2


Cloud environments are especially at risk:3

35%

have compute assets that are vulnerable to attackers

29%

have exposed assets containing personal information

12%

have exposed containers with critical or high-severity vulnerabilities

Sources: 1sentinelone.com, “Top 12 Cloud Security Challenges,” April 10, 2026; 2drj.com, “2026 Cloud Security Report Data Reveals ‘Complexity Gap’,” Jan. 26, 2026; 3Wiz, “Cloud Data Security Snapshot: Current Exposure Trends,” May 2025

Why Cloud Monitoring Matters

The process of monitoring cloud-based systems for risks and misconfigurations is known as cloud security posture management. Here’s why CSPM is an essential component of any cloud-native application protection platform.

80%

of cloud security breaches are a result of misconfigurations1

70%

of organizations say tool sprawl and visibility gaps are top barriers to cloud security2

Cloud environments are especially at risk:3

35%

have compute assets that are vulnerable to attackers

29%

have exposed assets containing personal information

12%

have exposed containers with critical or high-severity vulnerabilities

Sources: 1sentinelone.com, “Top 12 Cloud Security Challenges,” April 10, 2026; 2drj.com, “2026 Cloud Security Report Data Reveals ‘Complexity Gap’,” Jan. 26, 2026; 3Wiz, “Cloud Data Security Snapshot: Current Exposure Trends,” May 2025

Full Visibility With Wiz Go

After a short demo of the product organized by CDW and led by Wiz, the customer decided to purchase Wiz Go, a bundle that includes three key modules. The first, Wiz Code, provides CI/CD workflow scanning to find vulnerabilities in code, registries and images. The second, Wiz Cloud, uses cloud-native APIs to identify and prioritize risks in the public cloud environment. Finally, Wiz Defend provides runtime protection and cloud-threat detection and response capabilities.

Oben provided onboarding services for Wiz Code and Wiz Cloud to help the customer operationalize its new system, and he ultimately ensured it had full visibility into all of its cloud-based assets. “We started by connecting to Azure, since that was the team’s primary objective,” he notes, “and then we did the same for their other cloud platforms,” including Snowflake, Okta and Microsoft 365.

Today, Oben and Cappiello say, the organization leverages Wiz around the clock, and its head of security recently reported that outcomes so far have been overwhelmingly positive:

  • Full visibility and compliance into all cloud assets within the organization’s public cloud environment
  • Comprehensive security integration at every step in the CI/CD pipeline
  • Correlated security alerts with contextual data across the entire software development lifecycle
  • Significant time and cost savings related to cloud monitoring by IT

“You look at their team and the challenges they faced, and it’s like this solution was purpose-built for them,” Cappiello says. “Now they know exactly what they’re running in the cloud, and when there’s a problem, they know what to do.”